1. Data Protection

We are committed to handling personal information responsibly and only for legitimate business purposes. Our approach includes:

  • Purpose-based processing.
  • Access limited to authorised personnel.
  • Appropriate confidentiality obligations.
  • Data retention based on business, contractual and legal requirements.
  • Data masking where appropriate.
  • Client-specific data handling requirements.
  • Cooperation with clients regarding applicable data-protection obligations.

Oxyvin does not sell customer personal information as a business model.

2. Security by Operating Model

Client-Controlled Environment

Where appropriate, clients can provide agents with access to their own CRM, dialer or contact-center environment. This allows the client to maintain control over system access, user permissions, DLP policies, endpoint controls, data retention, recording policies and internal security requirements.

Oxyvin-Managed Environment

Where Oxyvin operates the environment, we apply appropriate operational and technical controls based on the nature of the engagement. These may include access controls, authentication, data masking, restricted system permissions, monitoring, confidentiality requirements and controlled access to recordings and reports.

3. Workforce Responsibility

Oxyvin operates a distributed customer-engagement workforce. We are committed to maintaining documented and transparent engagement arrangements with the people who deliver our services. Our approach includes written engagement terms, clearly defined assignments and responsibilities, transparent compensation arrangements, appropriate payment and tax documentation, operational policies, confidentiality obligations, appropriate conduct requirements, and compliance with applicable workforce requirements. We review our workforce practices as applicable laws and regulations evolve.

4. Client Transparency

We believe clients should have visibility into the customer engagement operation they are paying for. Depending on the engagement, clients may receive visibility into campaign performance, agent activity, login status, call outcomes, call recordings, historical reports, productivity metrics and campaign-level results.

Oxyvin seeks to operate in accordance with applicable laws and regulations relevant to its business and the services it provides. This includes requirements relating to data protection and privacy; information security; telecommunications and customer communications; consumer protection; taxation; employment and workforce arrangements; confidentiality; and contractual obligations. Oxyvin also recognises that compliance requirements may differ based on the client’s industry, location, campaign and the type of personal information involved.

6. Client Responsibility

Compliance is a shared responsibility. Clients remain responsible for ensuring that customer data supplied to Oxyvin has been lawfully obtained; calling lists and communication instructions are appropriate; required permissions, notices or consents have been obtained; campaign scripts and offers are accurate; and Oxyvin receives lawful and appropriate instructions.

7. Continuous Improvement

Security and compliance are not one-time activities. Oxyvin periodically reviews its operating practices, technology environment, workforce processes and contractual requirements to identify opportunities to strengthen its controls.

“We believe customer engagement should be flexible without compromising responsibility. Our commitment is to combine people, technology, transparency and responsible operating practices so that clients can scale customer engagement with confidence.”Our Commitment

Questions about this policy?

Reach out to our team and we’ll be glad to help.

Talk to Oxyvin